Critical Flaw in Microchip ASF Exposes IoT Devices to Remote Code Execution RiskThe Hacker News·Sep 23, 09:58 UTC · Sep 23, 2024VulnerabilityCVE-2024-7490CVE-2024-2001760
The Apache Log4j team talks about the Log4Shell patching processThe Record·Jan 17, 00:00 UTC · Jan 17, 2023Vulnerability30
Friday Squid Blogging: Editing the Squid GenomeSchneier on Security·Aug 15, 00:00 UTC · Aug 15, 2020Policy & legal30
Apache releases the third patch to address a new Log4j flawSecurity Affairs·Dec 18, 15:20 UTC · Dec 18, 2021Vulnerability in the wildCVE-2021-45046CVE-2021-44228CVE-2021-45105160
Apache OpenOffice users should upgrade to newest security release!Help Net Security·Apr 22, 12:07 UTC · Apr 22, 2025VulnerabilityCVE-2021-33035CVE-2021-40439CVE-2021-41830+3 CVEs47
New Apache Log4j Update Released to Patch Newly Discovered VulnerabilityThe Hacker News·Dec 29, 05:00 UTC · Dec 29, 2021Vulnerability in the wildCVE-2021-44832CVE-2021-44228CVE-2021-45046+2 CVEs60
Second Log4j Vulnerability (CVE-2021The Hacker News·Dec 18, 13:56 UTC · Dec 18, 2021Vulnerability in the wildCVE-2021-45046CVE-2021-4422860
Vulnerability Spotlight: Code execution vulnerability in Microsoft Media FoundationCisco Talos·Feb 11, 19:31 UTC · Feb 11, 2020Vulnerability in the wildCVE-2020-0738160
Apache Tomcat Patches Important Remote Code Execution FlawThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2019VulnerabilityCVE-2019-023260
Apache MINA CVE-2024-52046: CVSS 10.0 Flaw Enables RCE via Unsafe SerializationThe Hacker News·Dec 27, 06:46 UTC · Dec 27, 2024Vulnerability in the wildCVE-2024-52046CVE-2024-56337CVE-2024-45387+2 CVEs160
Apache fixed a critical SQL Injection in Apache Traffic ControlSecurity Affairs·Dec 26, 00:43 UTC · Dec 26, 2024VulnerabilityCVE-2024-45387CVE-2020-17530160
Critical SQL Injection Vulnerability in Apache Traffic Control Rated 9.9 CVSS — Patch NowThe Hacker News·Dec 25, 13:30 UTC · Dec 25, 2024VulnerabilityCVE-2024-45387CVE-2024-43441CVE-2024-56337160
Apache Tomcat Vulnerability CVE-2024The Hacker News·Dec 24, 06:06 UTC · Dec 24, 2024VulnerabilityCVE-2024-56337CVE-2024-50379CVE-2024-1282860
PoC exploit for critical Apache Struts flaw found onlineHelp Net Security·Nov 20, 11:02 UTC · Nov 20, 2023Exploit / PoCCVE-2018-11776CVE-2017-563860
Apache Issues 3rd Patch to Fix New HighThe Hacker News·Dec 20, 05:02 UTC · Dec 20, 2021Vulnerability in the wildCVE-2021-45105CVE-2021-45046CVE-2021-4422860
Space and Cyber: The Race Above and the Battle BelowRecorded Future·Jun 4, 00:00 UTC · Jun 4, 2026Ransomware60
Critical Apache HTTP/2 Flaw (CVE-2026The Hacker News·May 5, 16:46 UTC · May 5, 2026Exploit / PoCCVE-2026-2391860
Magniber ransomware: exclusively for South KoreansMalwarebytes Labs·Jan 13, 08:15 UTC · Jan 13, 2026Ransomware57
Apache Foundation fixed a severe Tomcat vulnerabilitySecurity Affairs·Dec 24, 08:31 UTC · Dec 24, 2024VulnerabilityCVE-2024-56337CVE-2024-5037947
Apache Cordova App Harness Targeted in Dependency Confusion AttackThe Hacker News·Apr 25, 16:14 UTC · Apr 25, 2024Vulnerability142
US lawmakers tell TikTok CEO the app ‘should be banned’The Record·Mar 23, 16:49 UTC · Mar 23, 2023Policy & legal30
Apache fixes actively exploited web server zeroThe Record·Dec 16, 00:00 UTC · Dec 16, 2022Exploit / PoC in the wildCVE-2021-4177360
Hackers Started Exploiting Critical "Text4Shell" Apache Commons Text VulnerabilityThe Hacker News·Oct 24, 05:48 UTC · Oct 24, 2022Vulnerability in the wildCVE-2022-42889CVE-2022-3398060
Researchers Find Bugs in Over A Dozen Widely Used URL Parser LibrariesThe Hacker News·Aug 2, 11:07 UTC · Aug 2, 2022VulnerabilityCVE-2021-33056CVE-2021-23414CVE-2021-37352+5 CVEs160
Tech Giants to Team-Up on Open Source Security After White House MeetInfosecurity Magazine·Jan 14, 09:04 UTC · Jan 14, 2022Vulnerability55
CISA, FBI and NSA Publish Joint Advisory and Scanner for Log4j VulnerabilitiesThe Hacker News·Dec 29, 03:34 UTC · Dec 29, 2021VulnerabilityCVE-2021-45046CVE-2021-45105CVE-2021-44228+2 CVEs47
China suspends deal with Alibaba for not sharing Log4j 0The Hacker News·Dec 23, 15:13 UTC · Dec 23, 2021Vulnerability in the wildCVE-2021-4422860
While attackers begin exploiting a second Log4j flaw, a third one emergesSecurity Affairs·Dec 18, 14:00 UTC · Dec 18, 2021RansomwareCVE-2021-45046CVE-2021-4422860
Hackers Begin Exploiting Second Log4j Vulnerability as a Third Flaw EmergesThe Hacker News·Dec 17, 05:54 UTC · Dec 17, 2021VulnerabilityCVE-2021-45046CVE-2021-4422847
Critical RCE 0day in Apache Log4j library exploited in the wild (CVE-2021-44228)Help Net Security·Dec 13, 12:51 UTC · Dec 13, 2021Exploit / PoC in the wildCVE-2021-4422860
Week in review: Strengthening firmware security, Help Net Security: XDR Report releasedHelp Net Security·Oct 17, 00:00 UTC · Oct 17, 2021Ransomware in the wildCVE-2021-33035CVE-2021-30883CVE-2021-4044960
Friday Squid Blogging: Squid Orders Down in ItalySchneier on Security·Mar 20, 16:18 UTC · Mar 20, 2020Industry30
Yoroi-Cybaze ZLab released a free decryptor for Loocipher RansomwareSecurity Affairs·Jul 15, 13:15 UTC · Jul 15, 2019Ransomware57
Apache Tomcat Patches Important Security VulnerabilitiesThe Hacker News·Jul 24, 11:36 UTC · Jul 24, 2018Vulnerability in the wildCVE-2018-8037CVE-2018-1336CVE-2018-803460
Apache Tomcat Patches Important Remote Code Execution FlawThe Hacker News·Oct 5, 11:16 UTC · Oct 5, 2017VulnerabilityCVE-2017-12617CVE-2017-12615260
In ExPetr/Petya’s shadow, FakeCry ransomware wave hits UkraineKaspersky Securelist·Jul 4, 18:22 UTC · Jul 4, 2017Ransomware57
Experts at RedSocks analyzed the massive WannaCry Ransomware attackSecurity Affairs·May 14, 09:31 UTC · May 14, 2017Ransomware57
Player 3 Has Entered the Game: Say Hello to 'WannaCry'Cisco Talos·May 12, 22:09 UTC · May 12, 2017Ransomware57